Title
A SysML Extension for Security Analysis of Industrial Control Systems
Abstract
The security of Industrial Control Systems (ICS) has become an important topic. Recent attacks have shown that inadequately protecting control systems could have disastrous consequences for society. This paper presents an extension for the Systems Modeling Language (SysML), allowing for the extraction of vulnerabilities from an industrial control system model. After a control system is modeled in SysML, the model is converted into input for a formal reasoning tool. This tool contains a logic theory which is used for the vulnerability extraction. The rules in this logic theory are inferred from the ICS-CERT vulnerability database and ICS security standards. Once the vulnerabilities have been extracted, they are included in the SysML diagrams of the model. The modeling approach allows the user to quickly see which changes to the system get rid of the reported vulnerabilities. It is also possible to mark certain components as compromised to see the consequences of attacks on these components for system security as a whole. The resulting analysis can be used to strengthen the security of the control system.
Year
DOI
Venue
2014
10.14236/ewic/ics-csr2014.1
ICS-CSR
Field
DocType
Citations 
Formal reasoning,Control system security,Theory,Computer security,Industrial control system,Security analysis,Control system,Engineering,Systems Modeling Language,Vulnerability
Conference
5
PageRank 
References 
Authors
0.78
8
4
Name
Order
Citations
PageRank
Laurens Lemaire192.96
Jorn Lapon2628.18
Bart De Decker326539.11
Vincent Naessens48619.70